
Password etiquette is not about inventing a 40-character passphrase you will forget by Friday. It is about habits that stop one breach from cascading into email, banking, payroll, and every SaaS tool you use.
Rules worth enforcing at work
- Unique password per important account—email, banking, payroll, and admin portals first
- Long beats clever—three or four random words beat “P@ssw0rd2024!”
- Never share passwords in chat, email, or sticky notes on monitors
- Do not reuse the company email password on shopping or personal sites
- Change passwords after a known breach or suspected phishing—do not wait for “cleanup day”
Password managers (yes, for small teams)
A reputable password manager lets people use strong unique passwords without memorizing chaos. Business plans add shared vaults for vendor logins so the “password is in Bob’s head” problem goes away when Bob is on vacation.
What password etiquette is not
- Changing every password every 30 days for no reason (modern guidance prefers change-on-suspicion + MFA)
- Writing passwords in a shared Excel file named Passwords.xlsx on the server
- Texting the Wi‑Fi password to every visitor in the group chat forever
NIST’s digital identity guidelines moved industry practice toward longer secrets and MFA rather than frequent forced rotation: NIST SP 800-63 overview.
Pair good passwords with two-factor authentication.
Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.

No responses yet